
7 min read
Fake Support Agents: How Impersonators Trick Tron Users into Giving Up Their Wallets
A wave of phishing messages went out claiming to come from the CoinWallet team at CoinsDo. The branding was close, the tone was right, and the story was mundane: you have funds pending, your wallet needs verifying. One campaign told recipients a pending transaction required verification and walked them toward making a payment to release it. Others pointed at cloned sites that harvested wallet credentials.
Nothing in that attack touched a smart contract. No approval was signed, no key was cracked, and no site was breached. Fake support agents work this way by design. The attack is a conversation, and a conversation is the one surface a wallet cannot defend.
Self-custody has no support desk, which is the gap fake support agents fill
The instinct is to call this a user education failure. It is closer to a product gap.
If your bank card is stopped, there is a number on the back of it. If your wallet has a problem, there is a Telegram group, a Discord, and a subreddit, none of which are staffed by anyone with authority over your funds. Self-custody removes the intermediary on purpose, and it removes the help desk along with it.
So when a user posts a public question about a stuck TRX transfer or a deposit that never arrived, they have created a vacancy. Someone will fill it within the hour. The scammer is not exploiting stupidity. They are answering a support request that nobody else was going to answer, which is precisely why the approach works on experienced users too.
What a fake support agent conversation sounds like
The tempo matters more than the content, and it runs in three movements.
It opens with competence. Correct terminology, calm phrasing, a plausible profile, and a reference to the specific thing you posted about. Frequently they solve a small problem for you first, or explain something accurately, because the goal of the first exchange is only to establish that you are talking to someone who knows more than you do.
Then it turns. Your wallet has been flagged. There is a pending compliance check. A transaction is stuck in an intermediate state and will fail after some deadline. The detail is fabricated but the shape is familiar to anyone who has dealt with a real financial institution, which is the point.
Then comes the ask, always framed as a procedure rather than a request. Confirm your recovery phrase so we can restore access. Complete this verification form. Sign this transaction so we can run a security audit on the wallet. Send a small verification payment and we will release the pending amount.
You will notice the ask never sounds like theft. It sounds like paperwork.
Three asks no legitimate team makes
There is no version of a real support process that includes any of the following, on any platform, for any reason.
Your seed phrase or private key, in any format, including a screenshot, a partial phrase, or a "recovery form" that collects it a few words at a time. Anyone holding it owns the wallet outright, which is what a seed phrase is for.
A payment to release, verify or unfreeze your own funds. Real fees come out of the transaction. They are never collected in advance by a person in a chat window.
A signature on a transaction you did not initiate. "Sign this so we can check your wallet" is a request to authorize something, and the only thing it can authorize is a transfer or an approval.
Before any of those, one question resolves the whole category: did you contact them, or did they contact you? Official moderators and support teams do not open direct messages first. If the conversation started with an inbound message, it is over, regardless of how well it has gone since.
The reverse version, where they hand you the wallet
A Tron-specific variant runs the con backwards, and it catches people who would never share a seed phrase because they believe they are the one taking advantage.
Attackers post working seed phrases publicly in Telegram and WhatsApp groups, framed as a leak or a careless mistake. The wallet is real and visibly holds USDT. Import it and you can see the balance sitting there. You cannot move it, because the account has insufficient TRX for the fee. So you send in a little TRX, and that TRX disappears immediately.
SafePal documented the mechanism: the wallet's owner permission was reassigned before the phrase was ever published, and the signing threshold raised to two. Any outbound transfer now needs the attacker's signature as well as yours. Victims see a SIGERROR or a message saying the private key for the address is not in their wallet. Funds go in and nothing comes out, exactly as designed.
A wallet somebody hands you was never yours.
If you already shared something, revoking will not save you
The standard Tron advice is to revoke your token approvals. For this scam, that advice is wrong, and following it costs you the minutes that matter.
If you disclosed a seed phrase or private key, the wallet is compromised at the root. Every address derived from that phrase belongs to the attacker now, and revoking an approval does nothing about it. Generate a new wallet on a device you trust, then move funds out in descending order of value, highest first, because you are in a race with somebody watching the same balance. Do not reuse the old phrase for anything.
Revoking only applies if what you signed was a transaction rather than a disclosure. In that case, audit your approvals on TronScan after you have secured the wallet, not before.
Then report the profile to the platform and post the details in the community channel you were using. That is not a formality. The next target is usually reading the same thread.
One rule, no exceptions
There is no exploit here to patch and no wallet setting that closes it. The attack runs entirely through a chat window, so the control has to be a rule about chat windows rather than a rule about wallets.
Mine is one line and it has never needed an exception: nobody who contacts me first gets an answer about my wallet. Everything else on this page is detail.

